Data Processing Agreement (DPA)

Effective date: June 2021

This Data Processing Agreement (“DPA”) explains how Alugha GmbH (“Alugha”, “we”, or “our”) processes Personal Data on behalf of our customers (“you”, “your”, or “Client”) when using our translation and localization services (the “Services”).

This DPA applies to all Personal Data we process for you under our Services Agreement or equivalent terms. It ensures compliance with GDPR (EU 2016/679) and other applicable data protection laws.

1. Roles and responsibilities

  • You (Client) are the Controller of the Personal Data you provide to us.
  • Alugha is the Processor of that data, acting only on your instructions to provide the Services.

2. How we process your data

2.1 Purpose We process Personal Data only to:

  • Provide the Services (e.g., translation, localization, processing speaker names).
  • Comply with legal obligations (e.g., tax or regulatory requirements).
  • Improve the security and functionality of the Services.

2.2 Types of Data We may process the following Personal Data as part of the Services:

  • Speaker names (e.g., employees, suppliers, or other individuals in your videos).
  • Audio/visual content containing Personal Data.
  • Any other data you provide to us for translation or localization.

2.3 Your Instructions

We will only process Personal Data based on your documented instructions or as required by law. If we cannot follow your instructions due to a legal obligation, we will notify you immediately (unless prohibited by law).

3. Sub-processors

We use the following third-party service providers (“Sub-Processors”) to help deliver the Services:

Sub-processor

Service

Location

Microsoft (Azure)

Cloud infrastructure

EU (Germany, Ireland)

OVHCloud

Cloud hosting

EU (Germany, France)

BunnyCDN

Content Delivery Network

EU (Slovenia)

Qencode

Video encoding

U.S.

Exoscale

Cloud hosting

EU (Austria, Germany), Switzerland

Hetzner

Cloud hosting

EU (Germany, Finland)

Mistral

AI Services

EU (France)

3.1 Adding or Changing Sub-Processors

  • We may add or replace Sub-Processors from time to time.
  • We will notify you in advance of any changes to this list.
  • You may object to a new Sub-Processor by terminating the Services if the objection cannot be resolved.

4. Data transfers outside the EU/EEA

4.1 Legal Basis For transfers of Personal Data to countries outside the EU/EEA we rely on:

  • Standard Contractual Clauses (SCCs) (EU Commission Decision 2021/914) for GDPR.

4.2 Your Rights

  • You can request a copy of the SCCs or other transfer mechanisms we use.
  • If a transfer mechanism is invalidated or no longer applies, we will notify you and work to find an alternative solution.

5. Security measures

We implement technical and organizational measures to protect your Personal Data, including:

  • Access Controls: Restricted access to data based on roles and responsibilities.
  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Physical Security: Secure data centers with 24/7 monitoring, fire suppression, and access controls.
  • Backup & Recovery: Regular backups with offsite storage and tested recovery procedures.
  • Incident Response: 72-hour breach notification to you in case of a Security Incident.
  • Employee Training: All staff handling Personal Data receive data protection training.

For a detailed list of our security measures, see Annex I: Technical and Organizational Measures (TOMs).

6. Data subject rights

We will assist you in responding to requests from Data Subjects (e.g., individuals whose data we process) to exercise their rights under GDPR, including:

  • Access to their Personal Data.
  • Rectification (correction) of inaccurate data.
  • Erasure (“right to be forgotten”).
  • Restriction of processing.
  • Data portability.

If we receive a direct request from a Data Subject, we will forward it to you without delay.

7. Data retention and deletion

  • We will retain Personal Data only for as long as necessary to:
    • Provide the Services.
    • Comply with legal obligations (e.g., tax or regulatory retention periods).
  • Upon termination of the Services, we will delete or return all your Personal Data, unless we are legally required to retain it.
  • We will certify in writing that all your data has been deleted or returned.

8. Security incidents

If we become aware of a Security Incident (e.g., data breach), we will:

  • Notify you without undue delay (and, where feasible, within 72 hours).
  • Provide details of the incident, including:
    • The nature of the breach.
    • The categories of data affected.
    • The likely consequences and remedial actions taken.
  • Assist you in fulfilling any legal obligations (e.g., notifying supervisory authorities or Data Subjects).

9. Audit rights

  • You or your designated auditor may request information to verify our compliance with this DPA, including:
    • Documentation of our Technical and Organizational Measures (TOMs).
  • We will cooperate reasonably with your audit requests, subject to confidentiality and security considerations.

10. Contact information

10.1 Data Protection Officer (DPO) For questions about this DPA or data protection, contact our DPO:

  • Name: Ralf Bopp (SOTEC GmbH)
  • Email: datenschutz@sotec.net
  • Address: Alugha GmbH, O7, 17, 68161 Mannheim, Germany

10.2 General Inquiries

11. Miscellaneous

11.1 Governing Law

  • This DPA is governed by the laws of Germany.

11.2 Changes to This DPA

  • We may update this DPA from time to time to reflect changes in laws, regulations, or our practices. We will notify you of any material changes.

11.3 Entire Agreement

  • This DPA (including its Annexes) replaces all prior agreements between us regarding the processing of your Personal Data under the Services.

Annex I: Technical and Organizational Measures (TOMs)

We implement the following security measures to protect your Personal Data:

1. Physical Security

  • Secure data centers with:
    • 24/7 monitoring.
    • Fire suppression systems.
    • Access controls (e.g., key cards, biometrics).
  • Restricted access to servers and storage media.

2. Network Security

  • Firewalls and intrusion detection/prevention systems.
  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Regular vulnerability scans and penetration testing.

3. Access Controls

  • Role-based access to Personal Data.
  • Multi-factor authentication (MFA) for sensitive systems.
  • Password policies (e.g., minimum length, complexity, regular rotation).

4. Data Integrity

  • Regular backups.
  • Redundant systems to prevent data loss.
  • Logging and monitoring of data access and modifications.

5. Employee Training

  • Mandatory data protection training for all employees.
  • Confidentiality agreements for staff handling Personal Data.

6. Incident Response

  • Dedicated incident response team.
  • 72-hour breach notification to you.
  • Post-incident reviews to prevent recurrence.